Pingolin Privacy Notice
Last Updated September 9, 2026
Version 1.0 · Effective date: September 9, 2026 · dated copy of this version
1. Who We Are
This Privacy Notice describes how Pingolin LLC (“Pingolin,” “we,” “our,” or “us”) collects and processes personal information when you interact with us — including by visiting our website at pingolin.com (the “Site”), creating an account, or using our applications and services, including Track and Note (together, the “Services”).
Pingolin builds privacy-first applications on end-to-end encryption. Track provides encrypted location sharing among the members of a group you create or join (a “Circle”); Note provides encrypted note-taking and sharing. The Services are for individuals and families for personal and household use — we do not offer a business or organizational plan, and this Notice contains no data processing terms for organizational use.
This Privacy Notice is part of the Pingolin Terms of Service, currently at pingolin.com/terms (the “Pingolin Terms”).
2. How Encryption Shapes This Notice
The Services use a zero-knowledge architecture. Your content is encrypted on your device before it reaches us, with keys your device generates and seals under a key derived from your password. We do not hold your decryption keys. We cannot read your content, and we cannot give it to anyone — including law enforcement — because we are technically unable to decrypt it.
Location is sealed with a key belonging to the Circle, not to you. Every current member of that Circle can decrypt it — and because the Circle’s key chain carries forward, so can anyone who joins later, including for the period before they joined.
Two things reach us unencrypted: anything you send us directly (we need to read it to answer you), and, if you enable server-side place lookup, the coordinates and search text you submit. This Notice is about the limited personal data we hold in readable form.
3. Personal Data We Collect
The personal data we collect depends on which Services you use and how you interact with us. We may collect the following types:
Account Information. Your email address (for account recovery and communicating with you); a display name, if you set one (shown to other members of your Circles); your encrypted master key and key pairs; and key derivation parameters. We do not store your password — signing in proves you know it without transmitting it, so there is nothing on our side to disclose.
Session and Security Information. Session and refresh tokens, device name and user agent for session management, and two-factor authentication credentials. If you turn on optional authentication logging, we record sign-in attempts — IP address, device name and timestamp — and show them to you. It is off by default, and the records are deleted when you turn it off.
Device and Registration Information. When you create an account, we run an automated check that the request comes from a real person and, in our mobile applications, an untampered one. Depending on your platform, this sends a token to Cloudflare, Google, or Apple. Our Google-free Android builds instead use a hardware attestation from the device, which we verify ourselves — nothing goes to Google or anyone else on that path. From an attestation we read the device’s verified-boot state, OS version, and patch level, and we do not keep it after the check.
Location Information (“Track”). Your location content is end-to-end encrypted. We hold, in readable form: device type and push notification tokens (to deliver notifications); user and device identifiers and day-level timestamp buckets (for routing and retention); routing and scheduling information for your places, alerts, destinations, check-ins, and per-Circle sharing settings; a copy of your email address and display name, so Track can show you to other members; a Circle activity log of who joined, left, or was removed, and when; and the mapping between your per-Circle location pseudonyms and your account — we hold this only because we could not otherwise find and delete your entries on request. A few more points about the location data we may collect:
- The event time your device records is encrypted and reaches us only as a day-level bucket; the time our servers received the record is held at full precision. For live sharing the two are close together, so we effectively hold a record of when each of your devices uploaded.
- Each arrival at, and departure from, one of your own places is recorded against you — including which place and which person, but not where the place is — and is kept for 90 days.
- Whether a check-in was marked “Safe Arrival” or “All Clear” is held in readable form, even though the message and position inside it are encrypted.
Server-Side Place Lookup. By default, Track resolves addresses and place names on your device and sends us nothing. If you turn on server-side lookup, the coordinates and search text you type reach us unencrypted. The request carries no account, session, or identifier — the application spends an anonymous, single-use credit — so we cannot attribute a lookup to you. We do not log the coordinates or search text, except that a failed lookup may be recorded in the geocoding server’s error log, which contains them.
Note Information. Your note content — bodies, titles, notebook names, attachments, and attachment filenames and file types — is end-to-end encrypted. We hold in readable form: each attachment’s size in bytes (counted against your storage allowance); note and notebook identifiers and sharing membership, including the owner’s and recipient’s email addresses for a shared note (needed to route it); sync timestamps and version counters; and the time and repeat rule of any reminder you set (so our servers can schedule it). A reminder’s content is encrypted, and the notification reaching your device carries no note content.
Contact and Communication Information: If you contact us for support, we collect your email address, your messages, anything you attach, and our replies. Support correspondence is held in a support system we run ourselves — not sent to a third-party helpdesk — and is not end-to-end encrypted, because we need to read it to answer you. Please do not send us your password, recovery key, or note contents you would rather we not read; we will never ask you for any of them.
Payment and Transaction Information: Where you purchase through Paddle or Apple, that party collects your payment details directly; we do not receive them.
What we do not collect: We do not use analytics or tracking scripts, advertising cookies, or advertising pixels. We do not collect browsing behavior, search history, or usage telemetry. We do not fingerprint your browser or device to identify or track you — the registration checks described above are the only device signals we request, used solely to block automated abuse. Our Android applications can keep a crash log; it is off by default, stays on your device, expires after 7 days, and is never sent to us.
4. Your Data
Your Data. “Your Data” means any data, content, or materials you create, upload, submit, or store through the Services. You keep all right, title, and interest in Your Data; Pingolin claims no ownership. Because Your Data is end-to-end encrypted, we cannot access, read, use, or monetize it — subject only to the two exceptions above: anything you send us directly, and, if enabled, server-side place lookup.
License. You grant Pingolin a limited, non-exclusive, worldwide, royalty-free license to store, copy, transmit, and convert Your Data between technical formats, in encrypted form, solely to provide the Services — sublicensable to the service providers named in this Notice solely so they can carry, store, or serve it on our behalf. The right to copy exists because our backups are copies; the right to convert formats exists so a change of storage engine or encoding does not make Your Data unreadable. This license gives us no right to access Your Data’s content, which stays encrypted throughout and which we could not read in any format, and it lasts only as long as we hold Your Data. You represent that you own Your Data, or hold the rights needed to grant this license.
Your Responsibility for Others in Your Circles. When you add someone to a Circle, you decide what is collected about them and for how long. Where that goes beyond purely personal or household activity, data protection law may impose obligations on you directly, including a lawful basis for collection and a duty to respond to that person. The “Circles: Joint Controllership” section below sets out how responsibility is divided between us. That division does not transfer your obligations to us, and nothing in this Notice or the Pingolin Terms is advice on your own position.
Export. You may export Your Data at any time, from any surface the application runs on. Exports are structured, machine-readable files, and an export you’ve taken outlives a Circle’s retention period and anything you later do to your account. Your device decrypts Your Data before writing the file, so an export taken without a passphrase is readable by anyone who gets it. You may set an optional passphrase, and a file sealed on one platform opens on the others. We cannot recover a lost export passphrase, and you are solely responsible for safeguarding your export files. We recommend keeping your own export rather than relying on a Circle or someone else’s account surviving.
5. How We Use Your Personal Data
We use the personal data we collect primarily to operate, deliver, and secure the Services, and also for the following purposes:
Providing the Services. To route encrypted data to the correct users, deliver push notifications, apply your plan tier, and process payments.
Communication. To send you technical notices, security alerts, and other administrative messages, and to respond to your requests, comments, or questions. This includes notices you need to act on — such as an administrator asking to take over a Circle you own — which we send by email as well as in the application, since a device that has stopped receiving notifications would not show it to you in time.
Security. To manage sessions, maintain audit logs, detect and prevent fraud and abuse, and enforce rate limits. Failed sign-in attempts count against both the originating address and the account, so someone else cannot lock you out of your own account.
Legal Compliance. To comply with legal obligations and to respond to valid legal process, as described below.
Other Purposes with Your Consent. For any other purpose that we communicate to you and to which you consent.
We do not use Your Data, or any data derived from it, to train, tune, develop, benchmark, or improve any machine-learning or AI model — ours or a third party’s — and we do not license or sell it for that purpose. This extends to derivatives, including model weights, embeddings, indices, and fine-tuning artifacts, and applies to aggregated and de-identified data as much as to Your Data itself. We do not try to re-identify data we have de-identified. We do not build user profiles, run behavioral analytics, or mine metadata. We do not sell, rent, or share your personal data with advertisers, data brokers, or anyone else for marketing, and we do not send marketing email.
6. Disclosure of Your Personal Data
We do not disclose or share your personal data outside Pingolin, except to the third-party service providers below, who help deliver the Services on our behalf. These providers are bound by data processing agreements limiting their use of personal data to the services they perform for us, and they receive the minimum data necessary. They are:
| Service Provider | Purpose | Personal data received |
|---|---|---|
| Cloudflare | Content delivery, denial-of-service protection, edge validation, encrypted object storage, and the bot check at registration | Traffic decrypted at the Cloudflare edge, including client IP addresses, request headers and cookies, and account email addresses during sign-in; a bot-check token; and encrypted database backups, so that Cloudflare durably holds encrypted copies of account metadata. Your encrypted content remains ciphertext throughout. Storage is located in Western Europe; the Cloudflare edge is a global network, and traffic is decrypted at whichever edge location you reach |
| Netcup | Server hosting and infrastructure, in Nuremberg, Germany | Encrypted data at rest; service-to-service traffic remains on our private network |
| Google (Firebase Cloud Messaging) | Android push notifications, standard builds only | Device tokens and routing fields only. No title and no message text |
| Google (Play Integrity) | Registration integrity, standard Android builds only | A signed device-integrity token issued by the device |
| Apple (Push Notification Service) | iOS push notifications | Device tokens; a notification title and line of text we write, naming no person and no place; and routing fields. These are not end-to-end encrypted to your device |
| Apple (App Attest) | Registration integrity, iPhone and iPad | A signed app-attestation token issued by the device |
| Proton | Receiving mail sent to our published addresses | Everything contained in a message you send to one of those addresses. Mail we send to you does not pass through Proton |
We may share your personal data in connection with, or during negotiations of, a merger, sale of assets, financing, or acquisition of all or part of our business. We will notify you by email as soon as we are permitted, and before the transfer wherever the law and the transaction allow. Whoever takes over is bound by this Notice as it stands at the time of the transfer, and any change that materially reduces your protections follows the notice process in “Changes to This Privacy Notice” below. Your encrypted content stays encrypted throughout, so a change of ownership gives the new owner exactly what it gives us: ciphertext.
We may disclose personal data to government or law enforcement officials, or private parties, where we believe it necessary to comply with a legal requirement or process — including civil and criminal subpoenas, court orders, and other compulsory disclosures. We will disclose only information requested through valid legal process, and will make reasonable efforts to notify anyone whose information we disclose, unless legally prohibited — in which case we will notify you once the prohibition lifts. Where lawful, we will give you a chance to object or challenge a request before we comply, and we disclose no more than the request requires.
Because we do not hold your decryption keys, we cannot produce your encrypted data’s contents in response to legal process. What can be compelled is the personal data we hold in readable form — for a location service, not a trivial category: your email address, display name, and account creation date; IP address records within the retention periods below; which Circles you’re in (and so who you share location with, and which days each of you shared a position); arrivals at and departures from your own places for 90 days; which of the three check-in types was used; Circle names and note-sharing membership; the email address on a pending invitation; your payment reference; and your support correspondence. A valid order may also require us to start retaining data about a specified account going forward. A court order in a dispute between two users is not a government request and does not change what we hold.
7. Circles: Joint Controllership
When someone adds you to a Circle, two parties are making decisions about your location data. That person decides whether to collect it at all, who else is in the Circle, and how long the history runs. We decide most of the means: encryption, where the data is stored, when it is deleted, and what the applications will and will not do. Under Article 26 of the General Data Protection Regulation (“GDPR”), that makes us joint controllers with that person for the location data in that Circle, and Article 26 requires us to define our respective responsibilities and make the essence of that arrangement available to you. This section is that arrangement.
The person who added you is responsible for having a lawful basis to collect your location at all, telling you what that basis is if you ask, and acting on your objection — whether by removing you from the Circle or accepting that you’ve left. That person is also responsible for anything they have exported and kept, which is held on their own device and beyond our reach.
We hold no key to a Circle. If you ask us for a copy of your location data, we can provide the encrypted records and surrounding metadata, but not the readable positions — only a device holding the Circle’s key can produce those. That is the same property that keeps us from reading your data, and it cuts both ways.
8. Location Data
We treat location as high-risk whether or not a particular record is sensitive, and we draw no special category of data from it.
Location sharing is provided under our contract with you and begins when you create or join a Circle. Where consent is the applicable basis — including under the sensitive-data provisions of US state law — you give it by joining a Circle, and withdraw it by leaving the Circle or switching off real-time sharing, without penalty or loss of other functionality. You may also object to any location processing based on legitimate interests.
Under US state law, precise geolocation is sensitive personal information in California and sensitive data in Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy legislation, generally requiring opt-in consent. See the Location Specific Notices in Annexure I below.
9. Your Choices
Account Information. You may access and change your account information in your account settings at any time, and export your data or delete your account from there too. Account deletion is irreversible: your encryption keys are destroyed in the live Services immediately, and your encrypted data becomes permanently unrecoverable from them. Residual copies persist in our encrypted backups for up to 31 days; we do not use those backups to restore individual accounts.
Sharing Controls: Within each Circle you can switch off real-time sharing, switch off sharing your location history, share an approximate position instead of an exact one, pause sharing for a period you choose, and switch off alerts other members have set on you.
Cookies: We use only strictly necessary cookies, for authentication and session management. We do not use advertising cookies, tracking cookies, or third-party analytics. Our web applications also store small operational values in your browser’s local storage, and key material in IndexedDB, sealed so a script on the page can ask it to decrypt but cannot read it out. None of it is sent to us, and all of it clears when you sign out. Because everything we store on your device is strictly necessary for a service you requested, no consent is required under applicable e-privacy rules.
10. Your Rights
Subject to certain limitations and exceptions allowed by law, Pingolin honors the following rights for individuals regardless of location:
- Access: You have the right to request access to the personal data we process about you, along with information about how we process it and the categories of personal data we process.
- Correction: You have the right to request that we correct inaccurate or incomplete personal data we process about you.
- Deletion: You have the right to request that we delete personal data about you. One limitation applies, and we mention it because it’s the one people ask about: your location entries in a Circle are sealed with that Circle’s key, which we do not hold, so while your account exists we cannot identify and delete your entries in another person’s Circle on request. Two things do remove them: deleting your account (which erases your entries from every Circle you were in), or leaving the Circle and letting its retention period expire.
Depending on where you live, you may have other rights in addition to those above — see the Location Specific Notices in Annexure I below.
Location of Processing. Pingolin LLC is established in the United States, but the Services are not hosted there. Our servers are hosted by Netcup in Nuremberg, Germany, and our object storage is located in Western Europe, so your data is stored in the European Union and your encrypted content remains there at rest. Two qualifications: the Cloudflare edge is a global network, so traffic between you and us is decrypted at whichever edge location you reach; and the push and integrity providers described above receive what is described above, on their own infrastructure.
Before acting on a privacy-related request, we take steps to verify the requester’s identity — ordinarily confirming control of the email address on the account, and, for a deletion request, confirming from a signed-in session. We will never ask you for your password or recovery key. If you do not provide the information we request, we may deny the request. We respond to legitimate requests within legally mandated timeframes, or otherwise within 45 days. To exercise any of these rights, contact us using any of the methods in the Contact Information section below.
11. General
Changes to This Privacy Notice. If we change this Privacy Notice, we will post the changes on our website, and the version they replace will remain available at a dated link. You can see when this Notice was last revised from the “Last Updated” line at the top of this page.
Security of Your Data. We use technical, organizational, and administrative measures designed to protect personal data against unauthorized access, use, and disclosure. However, no method of internet transmission or electronic storage is completely secure, so we cannot guarantee absolute security.
Personal Data Breach. If a personal data breach occurs, we will notify affected users by email without undue delay, describing — so far as we know at the time — the nature of the breach, when it occurred and when we discovered it, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken to address and mitigate it, and a contact point. We will update you as we learn more rather than delay the first notice. We will also notify the relevant supervisory authorities within their own deadlines and comply with US state breach notification laws.
A breach of our servers would not expose your encrypted data’s contents — only ciphertext and the personal data we hold in readable form.
Data Retention. We keep personal data only as long as necessary for the purpose it was collected for. Each period below is a maximum, not a target; where retention depends on an event rather than a period, the event is stated.
| Data | Retention |
|---|---|
| Account record, including email address and encrypted keys | Until you delete your account |
| Session record | Until the session ends, then deleted within 7 days; a session unused for 12 months is deleted |
| IP address and user agent held on a session | 30 days, then erased even if the session remains active |
| Security audit log, including IP address | 90 days; failed sign-in attempts 30 days |
| Optional authentication log | Until you turn the feature off, which deletes the records |
| Location history, free Circles | Viewable 2 days; deleted after a maximum of 3 days |
| Location history, premium Circles | Viewable 365 days; deleted after a maximum of 395 days |
| Location history after premium ends | Premium retention continues for 30 days, after which free-tier retention applies |
| Circle notification records | 90 days, or until you delete your account if sooner |
| Circle activity log | 13 months |
| Mapping between location pseudonyms and your account | Until you delete your account, in every Circle |
| Notes, notebooks and attachments | Until you delete them. A note shared with you is stored once, under the account of the person who shared it |
| Notes you have deleted | 30 days after deletion |
| Arrivals at and departures from your own places | 90 days, or until you delete your account if sooner |
| Push notification tokens | Deactivated after 60 days without use of the application on that device, or after three consecutive delivery failures; deleted a maximum of 365 days later |
| Push delivery records | 7 days |
| Notification records | 90 days; 30 days once read |
| Email verification and password reset records | 30 days and 7 days respectively |
| Subscription record | For as long as the subscription continues. See “Sales records” below |
| Support correspondence | 24 months from the last activity on the conversation, and sooner if you ask. Material under a legal hold is kept until the hold lifts |
| Mail sent to our published addresses | For as long as the purpose for which it was sent requires, such as a legal claim, an abuse or security investigation, or a regulatory request, and then cleared. This is stated as a criterion rather than a fixed period because a preservation obligation can outlast any period we could state here. You may ask us what we still hold |
| Encrypted backups | Rolling basis. Residual copies persist for a maximum of 31 days after account deletion |
Sales records. When you delete your account, we keep a record of completed sales — the email address and display name on the account, the subscription or credit purchase, the amount, the dates, and the payment provider’s reference — for 7 years, then delete it automatically. Nothing else survives deletion: no password or key material, no notes, no location data, and no record of what you used the Services for.
We may retain personal data beyond these periods only where law or valid legal process requires it, or where an account is involved in abuse.
12. Children and Family Location Sharing
Minimum age. You must be at least 16 to create an account. No consent — parental or otherwise — permits anyone under 16 to use the Services, whether on their own account or one a guardian creates and controls. If we learn an account holder is under 16, we will delete the account and all its data.
A minor’s own rights. A person aged 16 or 17 is a data subject in their own right. They may request access, correction, deletion, portability, or objection directly from us — including for an account a guardian created and controls — and we will respond to them. We do not need a guardian’s permission to respond, and we will not tell the guardian a request was made unless the law requires it. Send requests to [email protected].
No profiling of minors. We do not build behavioral or location profiles of any user, we do not direct advertising to minors, and we do not use a minor’s personal data for any commercial purpose beyond providing the Services.
The Children’s Online Privacy Protection Act (“COPPA”). COPPA applies to online services directed to children under 13, or with actual knowledge of collecting personal information from them. Pingolin is directed to families, not children — the Services carry no child-oriented content, characters, or advertising, and are not marketed to children. Our minimum age of 16 is above the COPPA threshold. If a child under 13 is placed on the Services in breach of the Pingolin Terms, we will delete the account and its data as soon as we learn of it.
13. Contact Information
You may contact us, or exercise any of your rights as described in this Privacy Notice, at:
- Privacy and data protection: [email protected]
- Help with the Services or your account: [email protected]
- By post: Pingolin LLC, 1401 21st St, Ste R, Sacramento, CA 95811, United States
If you believe any of your rights relating to the collection or use of your personal data have been infringed, please contact us using the information above.
Annexure I
Location Specific Notices
1. European Economic Area (“EEA”), Switzerland, and United Kingdom
Pingolin acts as a controller of the personal data we collect and use in providing the Services.
We may process your personal data on the following legal bases:
- Contract: To provide the Services you have signed up for, including account management, synchronization, push notifications, and location sharing within a Circle you create or join.
- Legitimate Interest: To secure the Services, including audit logging, fraud detection, rate limiting, and the registration integrity checks described above.
- Legal Obligation: To comply with our legal obligations, including the sales records described above.
- Consent: For optional features you turn on yourself, such as detailed authentication logging and server-side place lookup. You may withdraw consent anytime by turning the feature off, which deletes the records it created.
Automated Decision Making: We do not make automated decisions producing legal or similarly significant effects concerning you, within the meaning of GDPR Article 22. The only automated decision we make is the registration integrity check described above, which can prevent an account from being created; you may ask us to review that decision manually.
International Transfers: Because we collect your personal data directly from you, that collection is processing under GDPR Article 3(2), not a transfer requiring Standard Contractual Clauses, and your rights under this Notice apply to it in full. Standard Contractual Clauses do apply between us and the service providers described above, with the UK Addendum and Swiss equivalent where relevant. Our encryption protects the contents of your notes and locations wherever stored. It does not protect the personal data we hold in readable form, including your email address, which our network provider decrypts at its edge when you sign in.
Additional Rights: In addition to the access, correction and deletion rights described above, you have the following rights, subject to certain limitations and exceptions allowed by law:
- Restriction: You have the right to request that we restrict processing of your personal data.
- Data Portability: You have the right to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller. The export function described above provides this.
- Objection: You have the right to object to our processing, including processing based on legitimate interests.
- Revocation of Consent: Where our processing is based on your consent, you have the right to revoke that consent.
Complaints: You may lodge a complaint with your local data protection authority — the Information Commissioner’s Office in the United Kingdom, the Federal Data Protection and Information Commissioner in Switzerland, or the authority for the country where you live or work in the EEA. You do not have to raise it with us first, though we would prefer you did so we can address it. Because Pingolin has no establishment in the European Union, no single lead authority handles complaints about us, and your own national authority is the right one to approach.
Our Representative: Pingolin has appointed a representative under GDPR Article 27 for the EEA, the UK GDPR for the United Kingdom, and Article 14 of the Swiss Federal Act on Data Protection for Switzerland. The same company is separately our legal representative under Article 13 of the Digital Services Act. You may address a request to them instead of us, though you never have to — [email protected] reaches us directly and is usually quicker.
Data Protection Representative Limited, trading as DataRep
77 Camden Street Lower, Dublin, D02 XE80, Ireland
Registered in Ireland, company number 616588
Email: [email protected]. Please put “Pingolin LLC” in the subject line.
Web form: www.datarep.com/data-request
If writing by post, address the envelope to “DataRep” and not to Pingolin.
DataRep is not a support desk. Anything concerning your use of the Services, your subscription or your account should be sent to [email protected].
2. United States
This section provides additional disclosures for, and details the rights of, residents of certain US states, including California consumers under the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”).
Categories of Personal Information We Collect: The personal information we have collected in the last 12 months falls into the following categories established by the CPRA:
- identifiers (such as email address, display name, and user and device identifiers);
- personal information as described in subdivision (e) of Section 1798.80 of the California Civil Code (such as payment reference information);
- commercial information (such as the subscription tier purchased);
- internet or other network activity information (such as session records, user agent and device type);
- geolocation data, including precise geolocation;
- other information that does not fall into any category described under the CCPA (such as encrypted content you upload, which we cannot read).
We do not collect inference data. We draw no inferences about you and build no profiles.
Categories of Sources: We collect the above from you directly and automatically from your device. We do not purchase or obtain personal information from data brokers or other third parties, other than the payment and subscription status we receive from Paddle and Apple.
Categories of Third Parties Who May Receive Your Personal Information: The categories described in the Disclosure of Your Personal Data section above.
Retention: The retention periods for each category are set out in the Data Retention section above.
Sensitive Personal Information: Precise geolocation is sensitive personal information. We collect and use it only to provide the Services you requested — not to infer characteristics about you, and not for advertising. Because we make no use of sensitive personal information that the right to limit would restrict, we do not offer a “Limit the Use of My Sensitive Personal Information” option.
Pingolin does not sell your personal information and does not share it for cross-context behavioral advertising, as those terms are defined by applicable state law — and never has. We do not sell or share the personal information of any consumer we know to be under 16. We engage in no targeted advertising and no profiling toward decisions with legal or similarly significant effects, and we run no advertising or analytics technology on our website, so there is nothing for a universal opt-out signal like Global Privacy Control to act on. We honor such signals where they apply.
We do not disclose personal information to third parties for those third parties’ own direct marketing purposes.
De-identified Data: Pingolin may use de-identified data in some instances. We maintain it without attempting to re-identify it, and do not use it, or any derivative, to train or improve any machine-learning or AI model.
Non-Discrimination: Pingolin will not discriminate against any consumer for exercising their rights. We do not offer any financial incentive or any difference in price or service in exchange for personal information, so no notice of financial incentive is provided.
Data Broker Status: Pingolin is not a data broker and is not registered as one, because we collect personal information directly from you and have a direct relationship with you.
Additional Rights: In addition to the access, correction and deletion rights described above, you may have the following additional rights depending on the state in which you reside and subject to certain limitations and exceptions allowed by law:
- Access in a Portable Format: The right to receive your personal information in a portable format when exercising your right to access.
- Opt Out of Sales/Sharing or Targeted Advertising: As described above, we do not sell or share personal information or engage in targeted advertising.
- Consent to Sensitive Data Processing: In Virginia, Colorado, Connecticut, Texas and other states, precise geolocation is sensitive data requiring your consent. You provide that consent by creating or joining a Circle, and you withdraw it by leaving the Circle or switching real-time sharing off.
- Appeal: The right to appeal any refusal by Pingolin to act on a request. Submit your appeal to [email protected]. We will tell you in writing what action we took (or didn’t) and why. If your appeal is denied, you may be able to submit a complaint to your state’s Attorney General.